Mijn moeder was depressief. Dat ik het ook zou worden, voelde onvermijdelijk – juist daar ligt het probleem - De Correspondent

Sinds mijn moeder overleed, is me talloze keren gevraagd of depressie ‘in de familie zit’ – en, impliciet of expliciet, of ik niet bang ben dat er ook iets in mij zit. Ja, die angst zit er zeker. Maar inmiddels weet ik ook dat het zo niet werkt, en dat deze manier van denken zijn eigen gevaren met zich meebrengt.

Deze man bevocht apartheid én organiseerde Afrika's eerste Pride | Pride-special

Deze zomer is Amsterdam het middelpunt van de internationale queergemeenschap. Het is World Pride, twee weken vol feest én protest.

Europa brandt: bieden drones, satellieten en andere nieuwe technologie hoop?

Met enorme natuurbranden in Frankrijk, Spanje en Portugal staat Europa voor een nieuwe uitdaging: hoe temmen we zo snel mogelijk al dat vuur?

Planetenpad

We wandelen langs het Planetenpad bij het Herdenkingscentrum Westerbork en verdiepen ons in de op schaal geplaatste informatieborden over de planeten in ons zonnestelsel.

precies vier

Een Precies Vier bestaat uit 16 woorden, begrippen of namen, die moeten worden verdeeld in precies vier groepen van vier. Er is telkens maar één oplossing mogelijk. Welke woorden vormen een connectie?


crux

Een kruiswoordpuzzel, maar dan heel klein (en snel).


in het midden

Wie of wat staat er midden in het nieuws? Een actuele puzzel, die makkelijker is als je het nieuws een beetje volgt.


cinco

Als je wel zin hebt om te sudokuen, maar het liever bij een gridje van 5x5 houdt.


sudoku

Je krijgt een paar cijfers cadeau, maar het grid van 9x9 moet foutloos ingevuld worden.


The Register

Biting the hand that feeds IT — Enterprise Technology News and Analysis

America bans imported robots due to supply chain and security risks

The US government has decided to effectively ban the sale of advanced robots made in other nations. The decision trickled out over two days with publication of a National Security Determination [PDF] and an update [PDF] to the list of banned devices set by the Federal Communications Commission (FCC). The national security document observes “Advanced robotic devices will be critical to creating efficiencies in our economy, dominating on the battlefield, and securing our homeland” and notes that modern bots are now constantly connected to networks “which creates broad attack surfaces and leaves them vulnerable to data exfiltration, remote disruption of the physical robot, and dependencies on unsecure over the air updates.” One example of those vulnerabilities mentioned in the document is the UniPwn flaws that made it possible for attackers to take over humanoid robots made by Chinese company Unitree. “If the United States continues to rely on foreign sources of advanced robotic devices and critical components, it will subject the parts of the U.S. economy and national security enterprise that are reliant on these robots to the whims of foreign entities that could disrupt or degrade the supply chains at a time of their choosing,” the document states. To respond to those threats, the FCC decided the foreign-made advanced robotic devices belong on its Covered List of products for which imports are banned because they pose an unacceptable risk to the national security of the United States and its residents. The regulator offered a single exception: if the Department of War vouches for a device, it can have it. Foreign-owned companies that make their bots in America are also exempt, an important exemption because one of the leading robot-makers is Boston Dynamics – a company backed by the USA’s DARPA that is now majority-owned by South Korea’s Hyundai, but continues to manufacture its machines stateside. The decision does, however, apply to all future foreign-made devices. Vendors of clankers already approved for sale in the USA can continue to import them, and users are also free to use any bots they already own. But the intent of the documents is clear: from now on, only robots made in America are welcome in America. One entity that stands to benefit from this decision is Tesla, which Elon Musk claims will one day produce one million humanoid robots a year. In true Muskian style he has also said Tesla will go into “high production” of the bots in 2026, but there’s no evidence of that happening although the occasional trillionaire did recently show off the production line for Tesla’s “Optimus” bot. ®

A requiem for Optane, Intel's KV Cache killer that could have eased the RAM price crunch

History is littered with the corpses of technologies that were ahead of their time, and Intel’s Optane storage and memory products are certainly among them. Expensive, badly misunderstood, and awkwardly priced, the technology struggled to find a place in the market, surviving just five years before Chipzilla pulled the plug. Things might have been different if it were launched today. The shift from AI training to inference has driven tremendous demand for DRAM and NAND flash. In fact, the same properties that made Optane a niche product a few years ago would have made it ideally suited to these write intensive AI workloads. The rise and fall of Optane Intel and Micron co-developed Optane – or more specifically, 3D XPoint memory – and unveiled it in 2015. It promised to bridge the gap between conventional NAND flash used in SSDs and DRAM used in DDR4 and (later) DDR5. Like NAND, 3D XPoint was non-volatile, which means data persists when unpowered, making it appropriate for storage applications. But unlike NAND, 3D XPoint didn’t store data using trapped electrons and instead relied on a phase change material that was both extremely fast, achieving sub-10-microsecond latencies (even lower for later PMem modules), and absurdly write-endurant. Intel’s penultimate Optane SSDs boasted endurance of 100 drive writes a day and a mean time between failures of two million hours — specs that remain unrivaled today. Those figures are of course extrapolated, based on what we know about how 3D XPoint reads and writes data. But if anything, we suspect Intel was probably being conservative with its claims. This one-two punch of endurance and latency, particularly for random reads and writes meant that it could be used as a second tier of system memory. Optane SSDs are really, really low latency for storage-class memory, but they’re still orders of magnitude less responsive than DRAM which can hit 100 nanoseconds or lower. We should note Intel’s PMem DIMMs were capable of latencies of roughly 350 nanoseconds. Intel’s Optane persistent memory also had the benefit of capacities up to 512 GB per DIMM, at a time when the most you could expect out of DDR4 was about 128 GB – and only if you had deep pockets. These persistent memory DIMMs could be made to behave like main memory, with standard DDR4 functioning as a massive L4 cache when enabled; as a storage pool; or in an application-aware memory mode, which exposed the Optane memory directly to select applications. Despite Optane’s many strengths, it was rather awkwardly priced. For the same memory density, 3D XPoint was consistently more expensive than NAND and, while cheaper than DRAM, significantly less performant. As a result, there was rarely a scenario in which users were better off with Optane than they would be just buying more NAND or fewer, bigger DIMMs. To make matters worse, as the boffins at TechInsights noted at the time, while 3D XPoint had its merits, it wasn’t improving quickly enough to keep up with NAND flash on bit density. By 2021, Micron had had enough. The memory vendor announced it would end development of 3D XPoint products. With no source of new silicon for its SSD and persistent memory products, the writing was on the wall for Optane. Intel's then-CEO Pat Gelsinger officially pulled the plug in 2022, ending development of new products under the Optane banner. The P5810X and P5811X, the final Optane products to roll off the assembly line, launched in late 2022. Ahead of its time The same year Intel pulled the plug on Optane, a new workload was emerging that would completely turn the datacenter on its head, and might very well have been the killer app to justify 3D XPoint’s continued development. In November 2022, OpenAI, then a relatively obscure AI startup, lifted the curtain on ChatGPT, kicking off an AI arms race and sparking a massive influx of money into the tech sector. Large language models are among the most resource-intensive workloads in the world. But until 2025, most of that compute was dedicated to training bigger, smarter, and less hallucination-prone models. The arrival of DeepSeek early in that year signaled the shift toward inference, a workload that needs plenty of compute, memory, and storage. Modern inference engines are tuned to maximize efficiency. One way is by caching the key value pairs used to track model state. Chatbots and agents are inherently iterative. For multi-turn sessions, every prompt contains not only new information, but also every request and response that came before it. Recomputing all of that every time a new request is made is wasteful, so instead that information is computed, cached, and reused. The problem is at large context sizes and high concurrency, these KV caches can get rather large. A single 64,000-token sequence in a model like DeepSeek R1 can chew up four gigabytes of GPU memory. Multiply that across hundreds or thousands of users and it adds up quickly. Modern GPUs don’t have much memory, and what they do have is usually tied up hosting model weights. Many inference engines therefore support KV cache offloading, either natively or through plugins. Once GPU memory is exhausted or chat sessions stale, older chats are ejected to system memory. But DRAM is expensive, in short supply, and may not even be enough. In fact, Nvidia is reportedly cutting the amount of LPDDR5X shipped as part of its Vera Rubin platform. Because of this, KV caches where, for example, a user has walked away and the session has been idle for an hour or more, may be offloaded to flash storage arrays for longer-term storage. The problem is that KV caching is a write-intensive workload and NAND has a finite number of writes it can make before it’s shot. There's a lot of work being done to mitigate this, but the fact remains that if you write enough data to NVMe storage, eventually it wears out. Optane’s otherworldly write endurance and low latency, particularly when concerning small random writes which dominate KV-caching, would have made it a perfect choice for this workload. Optane’s successors One of the nails in Optane’s coffin was that Compute Express Link (CXL) was already on the horizon. If the primary reason for adopting Optane was to get your hands on a large pool of reasonably fast DRAM-like memory, then CXL offered all the benefits and none of the compromises. In effect, early CXL implementations were essentially a remote memory controller to which you could attach your choice of memory, DDR4 or DDR . Need more memory than your CPU supports? Just plug a CXL memory expander into a free PCIe slot and you were off to the races. Later revisions of the memory coherent protocol added support for pooling, and later sharing. However, CXL hasn’t changed the fact that DDR5 is expensive at the best of times, and we are currently living in the worst of times for DRAM prices. (With that said, while your CPU may only support DDR5, the CXL controller might still be able to use DDR4. This is exactly what Meta is doing to boost the memory capacity of its systems on the cheap.) In the absence of Optane, memory vendors have attempted to fill the void with write-optimized NAND of their own. Kioxia’s XL-Flash is one such example of storage class memory (SCM) that promises many of the same benefits as Optane, including advertised write latencies under 10 microseconds, and endurance up to 60 drive writes a day, through the use of SLC (1-bit per cell) memory. There’s also a crossover with CXL here. XL-Flash can be exposed as a CXL device to simplify memory tiering. Samsung also attempted to replicate many of Optane's qualities with its Z-NAND tech, but the tech still falls well short of 3D XPoint. Samsung is reportedly revamping the tech and aiming for a 15x performance increase over conventional NAND. Alas, neither quite lives up to Optane’s legacy. The tech was simply too far ahead of its time. Had Intel and Micron waited just a few years longer, it might have ridden the AI wave all the way to victory. ®

MCP gets an enterprise makeover

The Agentic AI Foundation, part of the Linux Foundation, has released an update to the Model Context Protocol (MCP) that aims to help enterprises adopt AI-based automation. Open-sourced by Anthropic in November 2024, MCP provides a way for AI applications (agents) based on models like GPT-5.6 Sol or Claude Opus 5 to connect to existing data sources, tools, or other applications. It defines how content is exchanged in a client-server architecture. "The new release is MCP’s most important since remote MCP first launched over a year ago," wrote David Soria Parra, a member of technical staff at Anthropic and co-inventor of MCP, in a blog post. "It is a leap in serving scalable MCP servers and takes all the lessons learned over the last 18 months to provide a robust foundation for MCP’s future." The latest version of the specification does away with the legacy stateful architecture, making it more like HTTP services where network requests do not need to retain the state of the session. "Historically, running MCP at scale required sticky routing or shared state to maintain continuity across sessions," explained Caitie McCaffrey, a Microsoft software engineer and core MCP maintainer, in a blog post. "This made large-scale production deployments complex to implement and operate even when the capabilities being exposed were stateless." The revised protocol changes the underlying architecture to eliminate the overhead of managing session state, which allows organizations to run MCP servers behind standard load balancers on existing Kubernetes and DevOps tooling. The version 2026-07-28 release also includes a Specification Feature Lifecycle and Deprecation Policy, because large companies want clear roadmaps and timelines when it comes to software changes. "The goal is a predictable timeline that SDK authors and implementers can plan migrations against when protocol surface area is retired," the documentation explains. The revised spec comes with a new policy that guarantees a minimum period of 12 months between feature deprecation and removal, which should please enterprise engineering teams, since they'll need to make fewer updates to MCP servers. On the security front, the latest spec revision adds Specification Enhancement Proposal (SEP) 2468, which calls for the inclusion and validation of an issuer (iss) parameter in authorization responses. This should help prevent OAuth Mixup Attacks. An attack of this sort can occur when an OAuth client connects to multiple OAuth providers via multiple MCP servers. If an attacker controls one of these servers, the miscreant could potentially obtain an access token or code from one of the other servers. Checking the iss parameter defends against that particular attack vector. Large organizations should also appreciate support for the Enterprise Managed Authorization extension, which makes it possible to manage MCP servers through a central identity provider. Another improvement involves the evolution of tasks – long-running tool calls or batch operations – into an extension. The main benefit is that tasks shift from a blocking request to an asynchronous request. "The payoff is operational resilience at scale," explains McCaffrey. "Because a task is durable and addressed by a stable handle, clients can persist task IDs to durable storage so that polling can resume after a crash or restart — no fragile, long-lived connections held open while waiting for work to finish, which the old blocking model forced on clients and servers that did not want to implement it." Other notable additions include header-based routing and cacheable list results. Some migration cost is expected, particularly for developers who implemented MCP code that relies on session identifiers. ®

Freemantle

Bass Photography has added a photo to the pool:

Freemantle

Western Australia

alice river - square-tailed kite

Fat Burns ☮ has added a photo to the pool:

alice river - square-tailed kite

Your comments and faves are greatly appreciated. Many thanks.

Square-tailed Kite
Scientific Name: Lophoictinia isura

Although it usually occurs singly, the Square-tailed Kite is sometimes seen soaring in pairs during the breeding season, and family groups of adults and one or two dependent young may be seen during post-fledging period. The Square-tailed Kite usually hunts by flying low over the treetops, occasionally plunging down through the foliage to snatch a bird or insect from among the leaves or twigs. The species often eats the nestlings of birds, and sometimes it will remove the entire nest to get at the young birds, and at other times may remove the tiny birds, one clutched tightly by the talons of each foot. They also catch adult birds by surprising them in the canopy of the forest.
Description: Often solitary, but can be seen in pairs when nesting. Squared-tailed Kites have a long, square tail with very long, upswept paddle-shaped wings and a large cream crescent at the base of their wing tips.
Similar Species: Immature Black Kite, Black-breasted Buzzard, and Red Goshawk
Distribution: Endemic to mainland Australia.
Habitat: The species mainly inhabits open eucalypt forests and woodlands, often where there is a broken canopy, but it also ranges into nearby open habitats. In southern Australia, Square-tailed Kites mainly inhabit open eucalypt forests and woodlands, often dominated by stringybarks, peppermints or box–ironbark eucalypts, as well as Woollybutt, Spotted Gum, Manna Gum, Messmate, River Red Gums, as well as other trees such as Angophora, cypress-pines and casuarinas. It also occurs along the edges of dense forest and along in road verges with remnant or planted trees, and in clearings within forest or in areas of regrowth, up to 4 years after the area has been logged. Other habitats which occasionally support Square-tailed Kites include mallee, heathland (mallee or coastal) and other low shrublands including saltbush plains, and also grasslands or open or cultivated farmland near remnant woodland.
Feeding: Searching for prey from the air, where they are highly agile at low levels, they mainly hunt in eucalypt open forest or woodland, and less often in low shrublands, heath, grassland or crops, and the margins between open and timbered country (forest–heath; woodland–heath; forest–open field; mallee–open paddocks; woodland edges; riparian timber; belts of trees in urban or semi-urban areas; and clearings in forests) are especially favoured. They specialise in hunting among trees, twisting between and below tree-tops, and they take most prey from the outer foliage of the canopy, but do not enter the canopy.
Breeding: Square-tailed Kites nest on horizontal branches in mature living trees, especially eucalypts, often near water, and they need extensive areas of forest or woodland surrounding or nearby.
Calls: Yelping, yeep, yeep, yeep. Also squealing ee ee ee ee
Minimum Size: 50cm
Maximum Size: 55cm
Average size: 53cm
Average weight: 568g
Breeding season: Aug - Dec
Incubation: 37 days
Nestling Period: 63 days
(Sources: www.birdsinbackyards.net/species/Lophoictinia-isura and www.birdlife.org.au/bird-profile/square-tailed-kite)

© Chris Burns 2026
__________________________________________

All rights reserved.

This image may not be copied, reproduced, distributed, republished, downloaded, displayed, posted or transmitted in any form or by any means, including electronic, mechanical, photocopying and recording without my written consent.

Measuring LLMs’ Ability to Perform Cryptanalysis

There’s new benchmark measuring AI’s ability to perform mathematical cryptanalysis. Anthropic’s frontier model actually found new attacks.

The benchmark: “CryptanalysisBench: Can LLMs do Cryptanalysis?” The idea is to benchmark the ability of LLMs to discover new mathematical cryptanalytic attacks against a series of historical algorithms.

Abstract: Cryptanalysis—the task of finding attacks against cryptographic schemes—its at the intersection of mathematical reasoning and cybersecurity, two areas where LLMs have advanced fastest. Cryptanalysis represents both a clean testbed for frontier reasoning (as practical attacks can be automatically verified) and a domain with unusually high stakes, since the primitives under study underpin our digital security. In this paper we ask whether LLMs can do cryptanalysis, and find that the answer is increasingly yes. We introduce CryptanalysisBench, 191 tasks across six families of cryptographic primitives (block ciphers, hash functions, etc.) drawn primarily from four NIST standardization competitions. Our benchmark consists of three tiers: (i) primitives with known practical breaks; (ii) primitives with no known practical break, evaluated both at full strength and as scaled-down variants; and (iii) a challenge set of production primitives at the frontier of cryptanalysis. Five frontier models (Claude Opus 4.8, Sonnet 5, Mythos 5, GPT-5.5, and the open-weights GLM-5.2) break 65%­86% of Tier 1 schemes, 6­12 Tier-2 schemes at full strength, and 24­61 across all scaled-down variants. Beyond deriving known results, models produce novel cryptanalysis, such as a key-recovery attack that exploits a design flaw in the SpoC AEAD and an error in KINDI’s published CCA-security proof, both to the best of our knowledge not previously known.

We release CryptanalysisBench as a tool to help track if (or when) AI cryptanalysis becomes a serious factor and as a scaffold for stress-testing candidate schemes before deployment. The attacks that the benchmark already surfaces are an early snapshot of a fast-moving frontier that may soon match, and in places exceed, the published state of the art.

Anthropic used the benchmark to test Mythos Preview, and found new vulnerabilities in Hawk and reduced-round AES.

Still early results, but this is definitely something to watch.

SlashDot thread.

Slashdot

News for nerds, stuff that matters

Apple Retires iPhone Upgrade Program For Klarna-Backed Leases

Apple has replaced its iPhone Upgrade Program with Apple Upgrade, a Klarna-backed U.S. leasing service covering most iPhones, iPads, Macs, and Apple Watches. MacRumors reports: Apple Upgrade has lower base prices than the iPhone Upgrade Program, with iPhones available starting at $17.99 per month and the Apple Watch available starting at $11.99 per month. Macs can be leased starting at $24.99 per month, and iPads start at $11.99 per month. AppleCare+ is optional and not included in the lease price, with customers also able to opt for AppleCare One. There are 12-month and 24-month leasing options for the iPhone and Apple Watch, along with 24-month and 36-month leasing options for the Mac and iPad. Lease cost varies based on device, and is lower with a device trade-in that's applied on a monthly basis. [...]

When leasing an iPhone, customers are required to choose a plan from AT&T, Verizon, or T-Mobile, and prepaid plans are not eligible. iPhones need to be leased with a carrier plan, but the iPhones are unlocked so customers can switch carriers if desired. MVNOs like Mint Mobile or Visible are not supported. At the end of the leasing period, customers can choose to return the device and exit the program, pay off the remaining amount owed on the device with a one-time payment and keep it, or return it and upgrade to a new device with a new lease.

The payoff amount is the difference between what was paid during the leasing period and the retail price of the device, minus any remaining trade-in credits. Klarna is not charging a fee for the leasing program, so an iPhone that's $1,099 can be leased and then purchased for $1,099 with no extra cost beyond taxes. As with trade-ins, Apple will send a pre-labeled and prepaid shipping box for device returns or upgrades. If you don't opt to pay the purchase fee at the end of the leasing program, you will not own the device and must return it. Last week, after Bloomberg reported on Apple's upcoming leasing program, 9to5Mac uncovered code in the iOS 27 beta suggesting the company was developing a system that could restrict leased iPhones when customers fall behind on payments. Apple has now told The Verge that the new "Restricted Mode" will not be activated in response to a missed lease payment. What the new system is actually meant for remains unclear.

Read more of this story at Slashdot.

AI-Found Bugs Aren't Proving Any Easier to Exploit Despite the Hype

AI-assisted vulnerability discovery has yet to produce the expected surge in real-world attacks: VulnCheck found that only 14 of 1,061 attributed discoveries, or 1.3 percent, had been exploited, which is "almost identical to the rate across all vulnerabilities in VulnCheck's dataset," reports The Register. "That's a far cry from the narrative that frontier AI is dramatically tilting the balance in attackers' favor by churning out instantly weaponizable bugs." The findings suggest AI is currently better at increasing the volume of bugs found than making them easier to weaponize. From the report: The report takes particular aim at Anthropic's much-publicized Project Glasswing, unveiled in April with warnings that AI-assisted vulnerability discovery could allow attackers to hijack systems, disrupt operations, or steal data. Claude Mythos may have identified 23,019 vulnerability candidates, but there's remarkably little public evidence showing what became of most of them. VulnCheck notes that only 126 have been published as CVEs, that just one has been confirmed exploited in the wild, and that Anthropic's public disclosure record has seen little movement since Project Glasswing launched.

But that doesn't mean AI-assisted vulnerability research has failed, according to Patrick Garrity, security researcher at VulnCheck. "AI-assisted vulnerability discovery clearly has value for both attackers and defenders," Garrity wrote. "The data does not suggest that AI-discovered vulnerabilities are inherently more likely to be exploited than those found through traditional methods." Instead, he argues, AI is simply helping researchers discover more flaws, giving defenders an opportunity to patch them before criminals get there.

Garrity stopped well short of declaring the threat overblown forever, but he did suggest some of the rhetoric has outpaced reality. "The data so far, including Anthropic's own stalled disclosure ledger, suggests that AI-assisted vulnerability discovery and frontier capabilities have been overhyped relative to the evidence available today," he wrote. "That doesn't mean the risk is imaginary. It means the impact has been real but modest."

Read more of this story at Slashdot.

eBay Reaches $56 Million Settlement With E-Commerce Newsletter Writers It Terrorized In 2019

eBay and several former executives have agreed to pay $56 million to Ina and David Steiner, the newsletter writers targeted in a 2019 corporate harassment campaign that involved threats, surveillance attempts, and deliveries of live insects and other disturbing items. The settlement closes the couple's civil case after seven former employees pleaded guilty to criminal charges related to the scheme. TechCrunch reports: Ina and David Steiner, a married couple and the co-authors of EcommerceBytes, inspired the ire of high-level eBay executives after occasionally criticizing the company in their newsletter. In 2019, a plot was concocted to intimidate the couple into halting their negative coverage. Executives used sock puppet social media accounts to harass the couple, while also sending them anonymous threatening letters and bizarre items in the mail -- including live spiders and cockroaches, pornographic magazines, a bloody pig mask, a funereal wreath, and a book about surviving the death of a spouse. According to previously released court documents, a plan that was attempted but never successfully carried out involved affixing a GPS tracking device to the couple's car. Yet another internally broached plan involved sending a "Samoan gang" to the Steiners' home.

The settlement this week resolves a 2021 civil case brought by the couple against eBay. The law office representing the Steiners writes that the settlement includes $46.15 million paid to the couple by eBay itself, as well as $2 million from former eBay executive CEO Devin Wenig. Additionally, $500,000 will be paid out to the couple from former eBay executive Wendy Jones, as well as $50,000 from former eBay executive Steve Wymer. Additional funds are being paid to various non-profits. In 2022, seven former eBay employees were criminally charged and pled guilty in relation to the plot, including the company's former security chief, James Baugh -- who was sentenced to nearly five years in prison. Others indicted by the U.S. Department of Justice include David Harville, Brian Gilbert, Stephanie Popp, Stephanie Stockwell, Philip Cooke, and former eBay contractor Veronica Zea.

Read more of this story at Slashdot.

Anthropic AI Model Finds Flaws in Tough-to-Crack Encryption Algorithms

Anthropic's Claude Mythos Preview has "found flaws in a weakened version of a digital encryption standard that is in pervasive use throughout the internet," reports The New York Times. Researchers said the model discovered novel attacks against weakened versions of AES and the experimental post-quantum HAWK system, including one that was 200 to 1,000 times faster than previous human-developed methods. From the report: The flaws identified do not concern a cryptographic standard currently in use today, which means that modern banking and communication systems are not subject to immediate potential intrusions from A.I. Instead, Anthropic's technology cracked a watered-down version of an algorithm for Advanced Encryption Standard, or A.E.S., a ubiquitous protocol that safeguards web traffic, wireless networks, data storage and more. It is common to perform tests on weaker versions of encryption algorithms to understand whether more powerful computers could someday crack the actual standards, akin to solving a simpler math problem to identify whether patterns may exist for a more complicated one. In the testing, Mythos was able to break the weaker version of Advanced Encryption Standard in a way that Anthropic said made an assault 200 to 1,000 times faster than what previous human research had managed to do. While the immediate ramifications are minimal, the long-term implications could be significant. In previous tests, large-language models seemingly could not match or best what humans can do in the mathematically dense field of cryptographic research, but their rapid advances could suggest a future in which top models can surmount traditional internet security protections that are foundational to just about everything that takes place on the internet.

[...] In addition to the attack on the encryption standard, Mythos also orchestrated another improved attack against a different digital cryptographic system known as HAWK that is designed to be bulletproof against both traditional and quantum computers. HAWK is not currently in use, but under consideration by the National Institute of Standards and Technology to become a new standard. The HAWK attack was validated by its authors, and independent cryptographers reviewed the Advanced Encryption Standard attack, Anthropic said, adding that it had shared its findings with the U.S. government and industry partners ahead of publication. Mythos devised the cryptographic attack on A.E.S. almost entirely autonomously, Anthropic said, but only after first refusing to contemplate the problem because it believed it was impossible to improve on existing methods of analysis. But after some coaxing, the chatbot sat with the puzzle for about a week before engineering its novel attack. Two human researchers then worked for nearly a month to verify that the method appeared correct. "Given that we are constantly underestimating the power and time of availability of future models, are we really comfortable that two years from now strong encryption won't be threatened?" said Glenn S. Gerstell, the former general counsel at the National Security Agency.

"Mathematicians would tell you that it shouldn't be possible given current computing powers to break strong encryption in any meaningful time," added Mr. Gerstell, who helped write a report on cryptology in 2022. "But I don't think the capabilities of future models in the medium term -- before quantum computing or quantum-proof cryptography -- should be dismissed as trivial in this context."

Read more of this story at Slashdot.

Snook.ca

Life and Times of a Web Developer

Chimed, I’m sure

A decade ago, when I was still speaking at conferences and heavily marketing myself, I’d often think of personal branding ideas. We’ve seen the trends. The business cards. The t-shirts. The stickers. The buttons. The socks! Can’t forget the socks. My logo is branded across not only my sites but my computers and my slide decks, too.

I also liked using colour to reinforce my brand. I’ve continued that tradition with green threading throughout the latest redesign. I even considering wearing green for all my conference talks. Thankfully, that ended up being a short-lived idea.

At one point in my career, I was getting interviewed for a number of podcasts and considered starting up my own podcast. One of the ideas that came out of preparing to start my own podcast was how to brand via audio. I liked the idea of doing chimes like the NBC chimes so that’s what I did:

It’s five dings in the pattern of how I spell out my last name: Ess Enn oh-OH Kay.

Had I implemented this, I had considered using it to intro my conference talks. I likely would’ve integrated it into the site somehow as well. Maybe clicking on the logo rings the chime as the letters of my name pop in sequence.

For now, I’ll simply document this little artifact of time.


Have something to say? Tell me about it.